Setup access to your ArchiveBox Server: {{ display_host|default:canonical_host }}
Browser-detected URL: Selected BASE_URL:
This is the main canonical URL for this server that will used in generated permalinks and some filesystem outputs. If you are able to setup wildcard DNS/TLS e.g. -> this server that is ideal, input just and select "isolated subdomains" below.
Auto: chooses one-domain/script-disabled replay for normal NAS and VPS hostnames, and automatically unlocks isolated full replay on *.localhost.
One domain, scripts disabled: the simplest self-hosted setup. It needs only one DNS record and one HTTPS certificate—or neither on a trusted local network. Risky HTML/XML/SVG scripts are blocked by CSP; trusted viewers and normal ArchiveBox UI/API JavaScript still work.
Isolated subdomains: allows full replay, including untrusted archived JavaScript, while separating each snapshot from the admin UI, API, and other snapshots. Remote access needs wildcard DNS and normally wildcard HTTPS.
Replay-only one domain: allows full archived JavaScript but disables login, admin UI, API, URL submission, and all state-changing requests. Every request is anonymous; private snapshots cannot be opened.
Dangerous shared domain: keeps admin UI/API and full archived JavaScript on one origin. A malicious saved page can trivially read archive data and attempt admin/API changes with your browser session.
Choose your UI permissions:
Live access preview
These examples update as you change the form. They show routing and anonymous exposure separately.
DNS:
TLS:
Can use high-fidelity web-archive viewers: (ArchiveWeb.page/WACZ)